Oh I think I might understand your ghost layer thing now. You want to have anti-forensic secondary storage, so that someone analyzing your decrypted dom0 would not be able to tell that the secondary storage even exists? Specifically, if it’s currently not hooked up then the affected VMs should still be able to start but with decoy data from primary storage?
              
              
              2 Likes